1. 미들웨어이야기/03. JBoss

JBOSS 버전정보 노출 방지

알 수 없는 사용자 2014. 7. 31. 16:04

버전정보 노출 방지 (Jboss-6.00 이하)

 $JBOSS_HOME/server/<CONFIGURATION>/deployers/jbossweb.deployer/web.xml

(X-Powered-By value 값 수정)

 <filter>

   <filter-name>CommonHeadersFilter</filter-name>

   <filter-class>

   org.jboss.web.tomcat.filters.ReplyHeaderFilter</filter-class>

   <init-param>

   <param-name>X-Powered-By</param-name>

   <param-value> Servlet 2.5; JBoss-5.0/JbossWeb-2.1</param-value>

   <init-param>

</filter>

 

$JBOSS_HOME/sever/<CONFIGURATION>/deploy/jbossweb.sar/server.xml  (server 값 추가)

 <Connector protocol ='HTTP/1.1" port="8080" address ="${jboss.bind.address}"

 connetionTimeout="20000" redirectPort="8443" server=" "/>

버전 정보는 공백 설정

                                                                                                                       by 김영준